Security
Responsible disclosure
We welcome reports from security researchers and work with them to resolve issues quickly.
Disclosure policy
Reporting a vulnerability
If you believe you have found a security vulnerability in a Reformsec website or service, please email info@reformsec.com with a description of the issue, the affected URL or component, and the steps needed to reproduce it.
Please do not include personal data belonging to others in your report, and do not publicly disclose the issue before we have had a reasonable opportunity to address it.
Scope
This policy covers websites and services operated by Reformsec under the reformsec.com domain. Systems belonging to our clients are out of scope: vulnerabilities in those systems should be reported to the organizations concerned.
Guidelines
Act in good faith, only test against systems in scope, and stop as soon as you have enough information to demonstrate the issue.
Do not access, modify or delete data that does not belong to you, do not degrade the availability of our services, and do not use social engineering, physical attacks or denial of service.
Our commitment
We will acknowledge your report, keep you informed of our progress, and credit you with your permission once the issue is resolved. We will not pursue action against researchers who follow this policy in good faith.
Machine-readable contact: /.well-known/security.txt